The Python Package Index (PyPI) has implemented new security measures to prevent domain resurrection attacks, a sophisticated supply-chain threat where malicious actors purchase expired domains to hijack user accounts through password reset mechanisms.
Since early June 2025, PyPI has proactively unverified over 1,800 email...
The Python Package Index (PyPI) has issued an urgent warning about an ongoing phishing campaign targeting developers who have published projects on the platform.
While PyPI itself has not been compromised, attackers are exploiting user trust through sophisticated domain spoofing techniques, attempting to steal...